Re: Bug#693421: Bug#693420: CVE-2012-5526: perl and libcgi-pm-perl: newline injection

2012-11-24 Thread intrigeri
Hi, Salvatore Bonaccorso wrote (24 Nov 2012 07:29:04 GMT) : > short addition to the mail before which I missed: For a possible t-p-u > upload I should choose 3.59+dfsg-1+deb7u1. Attached corrected debdiff. TL;DR --> I recommend to accept this unblock request for t-p-u. I have verified that I cou

Re: Bug#693421: Bug#693420: CVE-2012-5526: perl and libcgi-pm-perl: newline injection

2012-11-23 Thread Salvatore Bonaccorso
Hi short addition to the mail before which I missed: For a possible t-p-u upload I should choose 3.59+dfsg-1+deb7u1. Attached corrected debdiff. Regards, Salvatore diff -Nru libcgi-pm-perl-3.59+dfsg/debian/changelog libcgi-pm-perl-3.59+dfsg/debian/changelog --- libcgi-pm-perl-3.59+dfsg/debian/ch

Re: Bug#693421: Bug#693420: CVE-2012-5526: perl and libcgi-pm-perl: newline injection

2012-11-23 Thread Salvatore Bonaccorso
Hi Dominic, Niko, Security-Team and Release-Team On Sun, Nov 18, 2012 at 12:31:44PM +, Dominic Hargreaves wrote: > On Sun, Nov 18, 2012 at 12:08:21PM +0200, Niko Tyni wrote: > > Testing with the new testcases in CGI.pm-3.62, CVE-2012-5526 (CGI.pm > > newline injection in Set-Cookie and P3P hea